Knostic

Need-to-know access control for enterprise LLMs — stops AI oversharing before it becomes a breach.

Security & Safety Enterprise
Researched · Published · Reviewed
RECATOOLS Score
7.8 / 10
Capability
8.5
Value for money
6.5
Ease of use
7
ASEAN readiness
5.5
API quality
5
Founded
2023
HQ
Herndon, Virginia, USA
Users
Early-stage enterprise; ~9 customers (per Knostic, March 2025 — customers not publicly named)
Launched
April 11, 2024 (emerged from stealth)
Developer
Knostic, Inc. (independent)

Overview

Knostic is the world's first purpose-built IAM layer for Large Language Models, founded in late 2023 by cybersecurity veterans Gadi Evron and Sounil Yu. The platform sits between employees and enterprise AI assistants such as Microsoft 365 Copilot, Glean, and Google Gemini, dynamically shaping AI-generated responses so that each user receives only the information they are authorised to see — preventing salary data, M&A details, and regulated content from leaking through inference even when underlying files are technically accessible.

The product operates in three stages: pre-deployment query simulation (testing over 20 prompt patterns per persona to surface oversharing paths before go-live), runtime policy enforcement at inference time (role-based and topic-based rules applied to each response), and continuous monitoring with full audit trails aligned to EU AI Act, NIST AI RMF, and ISO/IEC 42001 requirements. The platform has expanded into AI agent security through its Kirin product line, which secures coding assistants, MCP servers, and IDE extensions against secrets leakage and destructive actions.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Enterprise (direct)
Custom
Direct sales contracts; terms vary by deployment
  • Custom scope and licensing
  • Free LLM Oversharing Tester tool
  • Quote via sales

Use cases

Securing a Microsoft 365 Copilot rollout in a regulated financial services or healthcare organisation to prevent salary, M&A, and patient data leakage Discovering shadow AI tool usage across an enterprise before an official AI governance programme is in place Generating audit trails and compliance documentation for EU AI Act, NIST AI RMF, or ISO/IEC 42001 assessments Protecting AI coding assistants and MCP servers from secrets exfiltration and destructive agent actions in software development pipelines Enforcing role-appropriate knowledge boundaries in enterprise search tools like Glean where multiple business units share a common index

What you can produce with Knostic

  • Pre-deployment oversharing risk report with quantified exposure score (0-100 readiness scale) across simulated user personas
  • Runtime need-to-know policy enforcement layer applied to every LLM response before it reaches the end user
  • Shadow AI inventory identifying unsanctioned AI tools in use across the organisation
  • Continuous policy drift alerts when data changes or permission structures shift
  • Full audit trail logs mapping each query, response, and data source for compliance review
  • Kirin AI agent security coverage for coding assistants, MCP servers, and IDE extensions
  • Executive dashboard with remediation recommendations for file labelling and permission adjustments
Advertisement

ASEAN Perspective

Knostic in Southeast Asia

Knostic has no confirmed APAC office or ASEAN-specific deployments as of mid-2026, though its March 2025 funding announcement noted "unprecedented interest from Japanese corporations" — a signal that the problem resonates in compliance-heavy Asia-Pacific enterprises. Investor DNX Ventures, a Japan-focused fund, provides a bridge into the Japanese market. For ASEAN buyers — particularly those in Singapore's financial sector or Indonesia's regulated industries deploying Microsoft Copilot — Knostic's core value proposition maps well to MAS Technology Risk Management Guidelines and PDPA obligations, but organisations should confirm data-residency and regional SLA terms directly before procurement.

RECATOOLS Verdict

Knostic fills a genuine gap that traditional DLP and IAM platforms miss: the inference-time leakage problem unique to LLMs, where an AI assistant can synthesise restricted knowledge from documents a user technically has read access to. Its pre-deployment simulation engine and runtime policy layer are technically differentiated, and its leadership roster — including the former NSA Director and multiple Fortune 500 CISOs on its advisory board — gives it strong enterprise credibility. The dual 2024 sweep of RSA Conference Launch Pad and Black Hat Startup Spotlight, followed by CB Insights AI 100 recognition in 2026, reflects genuine peer validation, not just marketing.

The caveats are real, however. At roughly $50,000 per annual contract, Knostic is firmly enterprise-tier and out of reach for SMEs or organisations in cost-sensitive markets. The platform's effectiveness is highly dependent on organisations already having mature role and topic taxonomies; deployments without well-defined policies will see limited uplift. Platform coverage, while strong for Microsoft 365 Copilot and Glean, remains narrower than broader AI governance suites. APAC-specific support, localisation, and regional data-residency assurances are not yet documented publicly, which is a consideration for buyers in Singapore, Japan, or Australia operating under local data protection regimes.

Independent AI-assisted assessment by RECATOOLS.

What people say

$50,000 a year is the entry point, per Knostic's AWS Marketplace listing — squarely enterprise-only, and a number worth knowing before you sit through a demo. Knostic sells need-to-know access control for enterprise LLMs: it sits between employees and tools like Microsoft 365 Copilot, Glean, and Google Gemini, and blocks the AI from synthesizing an answer out of documents a user technically has read access to but shouldn't be able to piece together — salary bands, M&A details, that kind of thing.

The credibility signals are unusually strong for a company this young. Founded in 2023 by Gadi Evron and Sounil Yu, Knostic is the only startup to sweep both the RSA Conference Launch Pad and Black Hat Startup Spotlight in the same year (2024), and its advisory board includes former NSA Director Mike Rogers alongside former CISOs from Reddit and Citibank. Total funding sits at $19.3 million, including an $11 million round in March 2025 and a $5 million RSAC Innovation Sandbox investment.

Technically, pre-deployment simulation (testing 20+ prompt patterns per persona before go-live) paired with runtime policy enforcement is a genuinely different approach from bolting DLP onto an LLM after the fact. The catch: it only works as well as your existing role and topic taxonomy, so organizations without mature access policies won't see much lift on day one. Coverage is currently strongest for Microsoft 365 Copilot and Glean; broader AI governance suites still cover more ground. No independent review-site ratings with meaningful volume turned up in this pass, and APAC-specific data-residency documentation is thin — worth asking about directly if you're buying from Singapore, Japan, or Australia.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • Knostic is the only startup in history to win both the RSA Conference Launch Pad and the Black Hat USA Startup Spotlight competitions in the same year (2024).
  • The company's name derives from 'gnosis' — knowledge — reflecting its focus on controlling what AI systems are permitted to reveal.
  • CTO Sounil Yu is the creator of the widely-adopted Cyber Defense Matrix framework, a visual model used by security teams globally to map defensive capabilities.
  • Despite being founded in late 2023, Knostic was named to the CB Insights 2026 AI 100 list of the world's most promising AI companies within roughly two and a half years of founding.

Frequently asked questions

What is LLM oversharing and why does Knostic exist to stop it?
LLM oversharing occurs when an enterprise AI assistant such as Microsoft 365 Copilot reveals sensitive information (executive salaries, M&A plans, personnel records) to a user who has indirect read access to source documents but should not see that synthesised conclusion. Traditional access controls gate file access but cannot block AI inference. Knostic applies need-to-know policies at the moment the LLM generates its response, reshaping or redacting the output before it reaches the user.
Which enterprise AI platforms does Knostic currently support?
Knostic's primary integrations are Microsoft 365 Copilot (including Teams, SharePoint, and OneDrive), Glean enterprise search, and Google Gemini Workspace. Its Kirin product line additionally covers AI coding assistants (VS Code, GitHub Copilot), MCP servers, and IDE extensions. Support for further enterprise AI platforms is on the product roadmap.
Does Knostic require rebuilding our existing permissions and access control architecture?
No. Knostic sits as an enforcement layer on top of existing IAM and data architectures rather than replacing them. It emulates user personas to discover oversharing paths, then applies topic- and role-based policies at inference time. Remediation recommendations such as file labelling and permission tightening are advisory; organisations can act on them incrementally without a full permissions overhaul.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Knostic's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Knostic unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Knostic directly →

Spotted something out of date? Suggest an update →

Advertisement